Privacy Policy
How we collect, use, and protect your information.
Last updated: August 2026
1. Information We Collect
Account Information
When you create an Morse account, we collect your email address, display name, and organization name. If you sign up via a third-party authentication provider, we receive the profile information you authorize.
Telemetry Data
Morse ingests observability data that you send via our SDKs or APIs. This includes agent execution traces, LLM call metadata (model, token counts, latency, cost), tool invocations, and custom annotations. The content and scope of this data is entirely controlled by your instrumentation code.
Usage Data
We collect standard web analytics to improve the platform: pages visited, feature usage patterns, browser type, and session duration. We do not use third-party tracking pixels or sell usage data to advertisers.
2. How We Use Your Information
- Provide the service: process and display your telemetry data, generate dashboards, trigger alerts.
- Improve the platform: analyze aggregate usage patterns to prioritize features and fix issues.
- Communicate with you: send transactional emails (alerts, account changes), and occasional product updates. You can unsubscribe from non-transactional emails at any time.
- Enforce our terms: detect abuse, prevent fraud, and maintain platform security.
3. We Do Not Train On Your Data
We do not use your telemetry data, traces, prompts, or completions to train, fine-tune, or otherwise develop any machine learning model — ours or anyone else's. Your data is processed to provide the Service to you and for no other purpose.
Morse features that use AI — the Copilot and the Anomaly Investigator — send the trace excerpts relevant to your question to our AI subprocessors at the moment you use them, after PII redaction. Those providers are contractually barred from training on data submitted through their APIs. If you do not use those features, your trace data is not sent to an AI provider at all.
Where we analyze usage to improve the platform, we do so on aggregated and de-identified metrics — never on the content of your telemetry.
4. Data Sharing
We do not sell your personal data or telemetry data.
We share data only with the following categories of third parties:
- Infrastructure providers: cloud hosting, managed database services, object storage, CDN and DNS providers — solely to operate the platform.
- Payment processor: Stripe processes billing information. We do not store your credit card details.
- Email delivery: transactional email services for alerts and account notifications.
- AI providers: only when you use the Copilot or Anomaly Investigator, as described above.
Every service we use is named individually on our Subprocessors page, with what it processes and where. We update that page and notify account owners at least 30 days before a new subprocessor begins processing customer data.
We may disclose information if required by law, subpoena, or court order, or to protect the rights, safety, or property of Morse or its users.
5. International Data Transfers
Morse is operated from the United States and your data is stored and processed there. If you are located in the European Economic Area, the United Kingdom, or Switzerland, your personal data is transferred outside your jurisdiction to reach us.
For those transfers we rely on the European Commission's Standard Contractual Clauses, incorporated into our Data Processing Agreement, together with supplementary technical measures — encryption in transit, tenant isolation, and configurable PII redaction applied before data is stored.
To request a copy of our Data Processing Agreement, contact [email protected].
6. Data Retention
Telemetry data retention varies by plan tier. See our Data Retention Policy for details.
Account data is retained for the lifetime of your account. When you delete your account, we remove all associated data within 30 days.
7. Your Rights
Access and Portability
You can access your telemetry data at any time via the Morse dashboard and API. You can export your data in JSON format.
Correction
You can update your account information at any time from your account settings.
Deletion
You can request deletion of your account and all associated data by contacting [email protected]. We will process requests within 30 days.
Objection and Restriction
You may object to processing or request restriction of your data by contacting us. We will comply unless we have a legitimate legal basis for continued processing.
8. GDPR (European Economic Area)
If you are located in the EEA, our legal basis for processing your personal data is:
- Contract performance: processing necessary to provide the Morse service you signed up for.
- Legitimate interest: improving the platform, ensuring security, and communicating product updates.
- Consent: where applicable, such as optional marketing communications.
You have the right to lodge a complaint with your local data protection authority.
9. CCPA / CPRA (California)
California residents have the right to know what personal information we collect, request access to it, request correction, request deletion, and opt out of the sale or sharing of personal information. You also have the right to limit the use of sensitive personal information and not to be discriminated against for exercising these rights.
We do not sell or share personal information as those terms are defined by the CCPA as amended by the CPRA, and we have not done so in the preceding twelve months.
To exercise your CCPA rights, contact [email protected].
10. Cookies
Morse uses essential cookies only — authentication tokens, session state, and your theme preference. These are required for the application to function and cannot be disabled while you are signed in.
We do not use third-party advertising cookies, tracking pixels, or cross-site remarketing.
Our public marketing site uses Google Analytics 4 in cookieless mode to measure aggregate traffic. It is configured with browser storage disabled and IP anonymization on, so it sets no cookies and does not identify you across visits or sites.
We also use PostHog for product analytics — which features get used, where people get stuck. PostHog does set a first-party analytics cookie, shared across morsehq.dev and app.morsehq.dev so that a visit and a later signed-in session count as one person rather than two. We do not enable session recording.
Your choice. If you are in the EU, UK, or EEA, we ask for your consent before PostHog loads, and nothing is stored if you decline. Elsewhere it is on by default. Either way, signed-in users can turn analytics off at any time under Settings → Integrations, and that choice is recorded against your account.
11. Security
We implement technical and organizational measures to protect your data, including encryption in transit, database-layer tenant isolation, scoped API keys, and configurable PII redaction applied at ingestion. See our Security & Trust page for the specifics and status.morsehq.dev for live availability.
12. Breach Notification
If we confirm a personal data breach affecting your data, we will notify you within 72 hours of confirmation, consistent with GDPR Article 33. The notice will describe what happened, what data was involved, what we have done, and what you should do.
Security contact: [email protected].
13. Children
Morse is a B2B service not directed at individuals under 16. We do not knowingly collect personal data from children.
14. Changes to This Policy
We will notify you of material changes by email or an in-app notice at least 30 days before the changes take effect.
15. Contact
For privacy-related questions or requests:
- Email: [email protected]
- General support: [email protected]